Strong passwords do not have to be impossible to type. Modern guidance puts more weight on length and uniqueness than on swapping letters for symbols in a short word.
Does this affect you?
Use this for email, banking, shopping, social media, work tools, and any account where you need a password that is both secure and usable.
What actually makes a password strong
Length and uniqueness matter more than old complexity tricks.
- Aim for at least 12 to 16 characters, and longer when the site allows it.
- Use a different password for every account. A strong password reused everywhere becomes weak as soon as one site is breached.
- Avoid predictable patterns such as password123456789, keyboard walks, birthdays, pet names, addresses, or favorite teams.
- Use passphrases made from several unrelated words when you must remember the password yourself.
- Do not reuse modified old passwords such as Summer2024 becoming Summer2025. Attackers know those patterns.
The short version: longer beats fancy, unique beats reused, and random unrelated words are easier to remember than a short symbol-heavy password.
A simple way to generate one
Use different approaches depending on whether you have a password manager.
- For normal accounts, let a password manager generate a long random password. You do not need to memorize it.
- For a master password or device password you must remember, choose four or five unrelated random words.
- Avoid words tied to your life, family, pets, school, or public social-media details.
- Add a number or symbol if the service requires one, but keep the passphrase long.
- Use a reputable strength checker or the account’s signup feedback as a rough check, but do not reuse a password just because it passes.
More control
Store strong passwords safely
A password manager is what makes unique passwords realistic. Without one, people tend to drift back to reuse.
Add two-factor authentication
A strong password is still one layer. Two-factor authentication keeps a leaked password from being enough to sign in.
Use maximum length on older sites
Some older sites force symbols and short maximum lengths. Meet their rules and use the longest password they allow.
Sources
- NIST Special Publication 800-63B – Digital Identity Guidelines (2025)
- CISA – Creating a password policy (2025)
- Google Safety Center – Create a strong password (2025)
